| 查杀引擎 | 查杀结果 | 查杀时间 | 查杀版本 |
|---|---|---|---|
| McAfee | Artemis!5329401CB03B | 20190524 | 6.0.6.653 |
| Alibaba | 20190513 | 0.3.0.4 | |
| Baidu | 20190318 | 1.0.0.2 | |
| Avast | 20190524 | 18.4.3895.0 | |
| Tencent | 20190524 | 1.0.0.1 | |
| Kingsoft | 20190524 | 2013.8.14.323 | |
| CrowdStrike | 20190212 | 1.0 |
| registry | HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome |
| registry | HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Mozilla Firefox |
| registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\firefox.exe |
| section | .ndata |
| suspicious_features | POST method with no referer header | suspicious_request | POST https://update.googleapis.com/service/update2?cup2key=10:3898791293&cup2hreq=dcf62f8c120d180b7a2706049f6916c806052ff37488cdf68cdacc927da1ef8c | ||||||
| request | GET http://c6m7w2m9.ssl.hwcdn.net/playtech_compressed_assets/casino_casinocom_new/index.7ze |
| request | GET http://fallback.playtech-installer.com/playtech_compressed_assets/casino_casinocom_new/index.7ze |
| request | GET http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab |
| request | GET http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEDlyRDr5IrdR19NsEN0xNZU%3D |
| request | GET http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEH1bUSa0droR23QWC7xTDac%3D |
| request | GET http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRDC9IOTxN6GmyRjyTl2n4yTUczyAQUjYxexFStiuF36Zv5mwXhuAGNYeECEHSfdSPcp6pyLdnEz5lZ6ec%3D |
| request | GET http://fallback.playtech-installer.com/playtech_compressed_assets/casino_casinocom_new/templates/installer/casinocom_2016.7ze |
| request | GET https://t8u4n6u7.ssl.hwcdn.net/stats.gif?data=refhUUF3kVcSNidkYCcBwwxRng81ln3yGSy8iY8gBZ4OANxAPzQshdRunVXbE7ceHmbkgRZ9OkztR7zkVUWzNjIHZ5NCubXNwc5SeVa04akTwlPPUhgvS4A0UJUz4se9Lwo2NmmcROW1KSYzppUUXqGq42vKeNJcGcRrDgoEpLSbIzTTvthM4RSQAyP5mnKgSM2AmSM07k3D%2FDe%2BwQKIaOCRqHgEibKdPGwBTq%2Fxs0ysbdVu%2FMZy7Ze2BpDnqQ2rREB4xD5EJZrI2uyfb58GWQJezuxYhGnn9vIkTfc821jfDc41Fplo7ON8z5ExDtUUnNI9KU%2FA8sOY18AtqFNH1pzoRp%2BaFakGyhc19eUSvch59baGy90y1toJREfqZFN2E9CPiTVHwcgjuRQWAMqwSo%2FVulOkK5wc1dH5jaXs5CuwhWcjslfdnte8bm1sx%2Fp%2Bx1FPAr2PFrJRMNXzJhdWgL%2F2HRcapmHaSB8djsVgAneVWOambKpsEm2LC%2Fh4IeC0k9Hx48obt%2Bwa97vrMasT3WflQnIQt231kelr1xFlEA%2F9S0C%2BV4fd5bybawcoK%2FC6uxRpkhntDcqwrQXZ6ze8GbHHzOAFWL%2BKzbb5oYC8up8KH6rIYiDHHu3KvjqHbODMGk8%2B%2FjTbv7Jb7s3z2ZSzURW8RcAYnNoTeY88uhz5CaA%3D |
| request | GET https://t8u4n6u7.ssl.hwcdn.net/stats.gif?data=KJiwtT5nYhMCkJQdg27BH%2FVxq2gpxeV12963w%2B3ofxF87QwOsoI1AylkVXTGVZQWacl6CjrIQ7CHFD9zKn4Cv0Z2cbHgYyjtga0UCuGji5g6sHT7U0F8XyYD%2FKpf8vOIXUunvufE7P8jnrIi9TC9vLWS8MWvnPyStRlNMMgOFNsFvt%2FLbUUvMF6g2WMtFWUegVbVu1RmJsjsiRc6F1OeaYL65xbZGKhebS6fqPDUH25%2FGLr1fH%2BPQvj%2B3d%2BNWeyCJh98pjOlr6pcSrSvlK2zV8THt6jotIu8JxN2W1lzMxXsUUgli9BGBugdFyuh4baGUDgC6t%2FNYo1oeHcEmDT9DLNBD54gZJbtnKfxWOKSxkKR8yG31tTOGg%2BUvo%2BRRl3A5zYEnykrAZrtL32DWIk%2BoGs3G%2Fr9aYJN3OL5Sj3Cu7SEaSerp223YtsF%2BCmktaCIKmkng5jYoZLfdX%2FDRd0421cuB%2FY3SxGjOk%2BydnCJNxG7D52lbMrYsFYQAlbpYIVAm9%2F55q0Hy3%2B1nK6Ljn5CxouPwtT4O8ZhrzLIj%2Fj0JENN4ojWtWD3FxaSeTPsiWFDlev4%2Ffs1QoDOtvlU%2Fk0zTtrkMgYYhxWzGPRh6q0El96eWWa6VkhLiAw5jv9xkPtJ9U%2BaamVsE82QOUucjwJOAWf%2BLbS23OANuIWXzlx3DmE%3D |
| request | GET https://c6m7w2m9.ssl.hwcdn.net/playtech_compressed_assets/casino_casinocom_new/templates/installer/casinocom_2016.7ze |
| request | POST https://update.googleapis.com/service/update2?cup2key=10:3898791293&cup2hreq=dcf62f8c120d180b7a2706049f6916c806052ff37488cdf68cdacc927da1ef8c |
| request | POST https://update.googleapis.com/service/update2?cup2key=10:3898791293&cup2hreq=dcf62f8c120d180b7a2706049f6916c806052ff37488cdf68cdacc927da1ef8c |
| registry | HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox |
| registry | HKEY_CURRENT_USER\Software\Mozilla\Mozilla Firefox |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nss5996.tmp\StdUtils.dll |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nss5996.tmp\internal5329401cb03b6543e7bd0e841baa5f36.exe |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nss5996.tmp\StdUtils.dll |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nss5996.tmp\internal5329401cb03b6543e7bd0e841baa5f36.exe |
| Time & API | Arguments | Status | Return | Repeated |
|---|---|---|---|---|
|
1620745312.908502 GetAdaptersAddresses |
flags:
0
family: 0 |
failed | 111 | 0 |
| host | 172.217.24.14 | |||
| Bkav | W32.HfsAdware.D664 |
| CAT-QuickHeal | Trojan.CGeneric |
| McAfee | Artemis!5329401CB03B |
| Cylance | Unsafe |
| K7GW | Riskware ( 005475191 ) |
| K7AntiVirus | Riskware ( 005475191 ) |
| TrendMicro | PUA.Win32.PlayTech.AK.component |
| Sophos | Generic PUA DD (PUA) |
| Invincea | heuristic |
| McAfee-GW-Edition | BehavesLike.Win32.BadFile.bc |
| Cyren | W32/Trojan.QHOV-7027 |
| Antiy-AVL | GrayWare[AdWare]/Win32.PlayTech.a |
| Endgame | malicious (high confidence) |
| Microsoft | PUA:Win32/Playtech |
| Zoner | PUA.Win32.65045 |
| ESET-NOD32 | Win32/PlayTech.A potentially unwanted |
| TrendMicro-HouseCall | PUA.Win32.PlayTech.AK.component |
| Rising | PUF.PlayTech!1.B889 (CLASSIC) |
| Fortinet | Riskware/PlayTech.A |
| registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D1EB23A46D17D68FD92564C2F1F1601764D8E349\Blob |